High 8.1
2026-05-07< 4.5.3
CVE-2026-7252
Minimum safe version
4.5.3
Update to 4.5.3 or later to address 6 fixable vulnerabilities
CVE-2026-7252
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
WordPress WP-Optimize Plugin < 4.2.0 is vulnerable to SQL Injection
CVE-2023-1119
WordPress WP-Optimize Plugin <= 3.2.11 is vulnerable to Cross Site Request Forgery (CSRF)
WP-Optimize <= 3.2.11 - Cross-Site Request Forgery